FFmpeg and Libav 'rpza_decode_stream()' Function Memory Corruption Vulnerability
BID:65549
Info
FFmpeg and Libav 'rpza_decode_stream()' Function Memory Corruption Vulnerability
| Bugtraq ID: | 65549 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 28 2013 12:00AM |
| Updated: | Nov 28 2013 12:00AM |
| Credit: | Mateusz "j00ru" Jurczyk and Gynvael Coldwind |
| Vulnerable: |
Libav Libav 0.8.10 Libav Libav 9.11 FFmpeg FFmpeg 2.1 |
| Not Vulnerable: | |
Discussion
FFmpeg and Libav 'rpza_decode_stream()' Function Memory Corruption Vulnerability
FFmpeg and Libav are prone to a memory-corruption vulnerability because it fails to adequately bounds-check user-supplied input before copying it to an insufficiently sized memory buffer.
Attackers can leverage this issue to execute arbitrary code in the context of the application. Failed attacks will cause denial-of-service conditions.
FFmpeg and Libav are prone to a memory-corruption vulnerability because it fails to adequately bounds-check user-supplied input before copying it to an insufficiently sized memory buffer.
Attackers can leverage this issue to execute arbitrary code in the context of the application. Failed attacks will cause denial-of-service conditions.
Solution / Fix
FFmpeg and Libav 'rpza_decode_stream()' Function Memory Corruption Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.